VYPR

CWE-276

Incorrect Default Permissions

BaseDraftLikelihood: Medium

Description

During installation, installed file permissions are set to allow anyone to modify those files.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-127 · CAPEC-81

CVEs mapped to this weakness (1,561)

page 41 of 79
  • CVE-2022-33877HigJun 13, 2023
    risk 0.46cvss 7.0epss 0.00

    An incorrect default permission [CWE-276] vulnerability in FortiClient (Windows) versions 7.0.0 through 7.0.6 and 6.4.0 through 6.4.8 and FortiConverter (Windows) versions 6.2.0 through 6.2.1, 7.0.0 and all versions of 6.0.0 may allow a local authenticated attacker to tamper…

  • CVE-2023-28079HigMay 30, 2023
    risk 0.46cvss 7.0epss 0.00

    PowerPath for Windows, versions 7.0, 7.1 & 7.2 contains Insecure File and Folder Permissions vulnerability. A regular user (non-admin) can exploit the weak folder and file permissions to escalate privileges and execute arbitrary code in the context of NT AUTHORITY\SYSTEM.

  • CVE-2023-28724HigMay 3, 2023
    risk 0.46cvss 7.1epss 0.00

    NGINX Management Suite default file permissions are set such that an authenticated attacker may be able to modify sensitive files on NGINX Instance Manager and NGINX API Connectivity Manager.   Note: Software versions which have reached End of Technical Support (EoTS) are not…

  • CVE-2022-4568HigMay 1, 2023
    risk 0.46cvss 7.0epss 0.00

    A directory permissions management vulnerability in Lenovo System Update may allow elevation of privileges.

  • CVE-2023-27647HigApr 14, 2023
    risk 0.46cvss 7.1epss 0.01

    An issue found in DUALSPACE Lock Master v.2.2.4 allows a local attacker to cause a denial of service or gain sensitive information via the com.ludashi.superlock.util.pref.SharedPrefProviderEntryMethod: insert of the android.net.Uri.insert method.

  • CVE-2023-25542HigApr 6, 2023
    risk 0.46cvss 7.0epss 0.00

    Dell Trusted Device Agent, versions prior to 5.3.0, contain(s) an improper installation permissions vulnerability. An unauthenticated local attacker could potentially exploit this vulnerability, leading to escalated privileges.

  • CVE-2023-0181HigApr 1, 2023
    risk 0.46cvss 7.1epss 0.00

    NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in a kernel mode layer handler, where memory permissions are not correctly checked, which may lead to denial of service and data tampering.

  • CVE-2022-45153HigFeb 15, 2023
    risk 0.46cvss 7.0epss 0.00

    An Incorrect Default Permissions vulnerability in saphanabootstrap-formula of SUSE Linux Enterprise Module for SAP Applications 15-SP1, SUSE Linux Enterprise Server for SAP 12-SP5; openSUSE Leap 15.4 allows local attackers to escalate to root by manipulating the sudo…

  • CVE-2022-33922HigOct 12, 2022
    risk 0.46cvss 7.0epss 0.00

    Dell GeoDrive, versions prior to 2.2, contains Insecure File and Folder Permissions vulnerabilities. A low privilege attacker could potentially exploit this vulnerability, leading to the execution of arbitrary code in the SYSTEM security context. Dell recommends customers to…

  • CVE-2021-41637HigJun 24, 2022
    risk 0.46cvss 7.1epss 0.00

    Weak access control permissions in MELAG FTP Server 2.2.0.4 allow the "Everyone" group to read the local FTP configuration file, which includes among other information the unencrypted passwords of all FTP users.

  • CVE-2021-40414HigJan 28, 2022
    risk 0.46cvss 7.1epss 0.01

    An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W v3.0.0.136_20121102. The SetMdAlarm API sets the movement detection parameters, giving the ability to set the sensitivity of the camera per a range of…

  • CVE-2021-40413HigJan 28, 2022
    risk 0.46cvss 7.1epss 0.01

    An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W v3.0.0.136_20121102. The UpgradePrepare is the API that checks if a provided filename identifies a new version of the RLC-410W firmware. If the version…

  • CVE-2021-26274HigJul 7, 2021
    risk 0.46cvss 7.1epss 0.00

    The Agent in NinjaRMM 5.0.909 has Insecure Permissions.

  • CVE-2021-1056HigJan 8, 2021
    risk 0.46cvss 7.1epss 0.02

    NVIDIA GPU Display Driver for Linux, all versions, contains a vulnerability in the kernel mode layer (nvidia.ko) in which it does not completely honor operating system file system permissions to provide GPU device-level isolation, which may lead to denial of service or…

  • CVE-2019-4652HigNov 12, 2019
    risk 0.46cvss 7.1epss 0.00

    IBM Spectrum Protect Plus 10.1.0 through 10.1.4 uses insecure file permissions on restored files and directories in Windows which could allow a local user to obtain sensitive information or perform unauthorized actions. IBM X-Force ID: 170963.

  • CVE-2019-5687HigAug 6, 2019
    risk 0.46cvss 7.1epss 0.00

    NVIDIA Windows GPU Display Driver (all versions) contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape in which an incorrect use of default permissions for an object exposes it to an unintended actor

  • CVE-2018-14335MedJul 24, 2018
    risk 0.46cvss 6.5epss 0.13

    An issue was discovered in H2 1.4.197. Insecure handling of permissions in the backup function allows attackers to read sensitive files (outside of their permissions) via a symlink to a fake database file.

  • CVE-2017-12699HigSep 9, 2017
    risk 0.46cvss 7.1epss 0.00

    An Incorrect Default Permissions issue was discovered in AzeoTech DAQFactory versions prior to 17.1. Local, non-administrative users may be able to replace or modify original application files with malicious ones.

  • CVE-2017-1382HigJul 24, 2017
    risk 0.46cvss 7.1epss 0.00

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 might create files using the default permissions instead of the customized permissions when custom startup scripts are used. A local attacker could exploit this to gain access to files with an unknown impact. IBM X-Force…

  • CVE-2025-48516MedMay 15, 2026
    risk 0.45cvss epss 0.00

    Insecure default configuration state of DDR5 memory module by AGESA Bootloader Firmware could allow an attacker with local user privilege to abuse the unprotected PMIC interface to create a permanent denial of service condition or affect the integrity of the memory module.